I'm brand new here. I'm collecting NetFlow traffic on an ethernet tap at home. One thing I've noticed is a ton of DNS traffic. I'm wondering why this is? Is it because outside machines are constantly asking my router for DNS information?

By using dig on the 2 outside hosts, I realize that they are the DNS servers for my ISP. So, I guess my question is still "why so much traffic?" Also, a lot of this traffic gets flagged by Snort as an alert because it thinks there are attempted DNS spoof attacks.